Skip to content

SLK-93353: Remove CAP_SYS_MODULE from enforcer daemonset#631

Open
andreazorzetto wants to merge 1 commit into
aquasecurity:masterfrom
andreazorzetto:az_SLK-93353_remove_sys_module
Open

SLK-93353: Remove CAP_SYS_MODULE from enforcer daemonset#631
andreazorzetto wants to merge 1 commit into
aquasecurity:masterfrom
andreazorzetto:az_SLK-93353_remove_sys_module

Conversation

@andreazorzetto
Copy link
Copy Markdown
Contributor

@andreazorzetto andreazorzetto commented Apr 2, 2026

Summary

Remove CAP_SYS_MODULE from the PKS enforcer daemonset template. The enforcer does not load kernel modules. Talos Linux blocks this capability, preventing the enforcer container from starting.

Related

The enforcer does not load kernel modules. Talos Linux blocks this
capability, preventing the enforcer container from starting.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant